First published: Sat Aug 31 2002(Updated: )
The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco PIX 501 | ||
Cisco PIX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0954 has a medium severity rating due to the potential for attackers to decrypt passwords easily.
To fix CVE-2002-0954, it is recommended to upgrade to a later version of the Cisco PIX Firewall that addresses this vulnerability.
CVE-2002-0954 may facilitate brute force attacks that can result in unauthorized access to the Cisco PIX Firewall.
CVE-2002-0954 specifically affects certain versions of the Cisco PIX Firewall, including the Cisco PIX 501.
While CVE-2002-0954 is relatively old, any remaining vulnerable systems still pose a potential threat if not updated or secured.